Take 107 - Ongoing

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 107

Released on 20 November 2019

PRJ-1336,
PRHF-3455

Security Management

Inline layers are not verified when there are no selected targets in the 'install on' column.

PRJ-4875,
PRHF-5274

Security Management

In some scenarios, when setting or modifying the Email/Phone fields of an administrator, the old values still appear at the bottom pane under "View Sessions" instead of the updated values.

PRJ-5557,
PMTR-43278

Security Management

In some scenarios, policy installation fails with "Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-2000117)". Refer to sk162554.

PRJ-5413,
PRHF-5815

Security Management

In some scenarios, policy Installation fails with "Operation failed, install/uninstall has been improperly terminated" error. Refer to sk162855.

PRJ-2984,
API-744

Security Management

In some scenarios, show generic-objects API command fails with "Management Server failed to execute command". Refer to sk157693.

PRJ-3379,
PMTR-39797

Security Management

In a rare scenario, the $CPDIR/tmp/ directory is filled with "CKP_mutex::_opt_CPsuite-RXX_fw1_log__..." files. Refer to sk36754.

PRJ-5495,
PRHF-5881

Security Management

NEW: Added the policy verifier memory enhancement and additional debugging options. Refer to sk162453.

PRJ-1248,
PRHF-2012

Security Management

High CPU utilization by FWM process when SmartEvent is enabled on the Security Management Server. Refer to sk147563.

PRJ-5023,
PRHF-4877

Security Management

In some scenarios, policy verification process fails for extremely large policies. Refer to sk161412.

PRJ-5424,
PMTR-41518

Security Management

In some scenarios, policy fetch fails if name of the Security gateway that tries to fetch this policy is not defined in DNS. Refer to sk150472.

PRJ-6942,
PRHF-6754

Security Management

In a rare scenario, policy installation fails with "Policy installation had failed due to an internal error". Refer to sk163482.

PRJ-4666,
PMTR-41210

Multi-Domain Management

The FWM process may unexpectedly exit when there is no valid license on the Multi-Domain Server.

PRJ-7007,
PRJ-6992

Multi-Domain Management

The Gaia restore of Multi-Domain Server fails when using Take 76 of R80.30 Jumbo Hotfix Accumulator. Refer to sk163473.

PRJ-3138,
PRJ-1343

SmartConsole

In some scenarios, DNS Maximum Reply Length IPS protection is not enforced.

  • To fully resolve the issue, R80.30 SmartConsole Build 20 (or higher) should be installed.

PRJ-1511,
PMTR-35845

SmartConsole

In some scenarios, Installation Targets do not show the correct gateways when cloning and editing the installation targets in the same session.

PRJ-1882,
PRJ-783

SmartConsole

In some scenarios, user cannot delete a VS object since it is referenced by an automatically generated exception rule. Refer to sk167272.

PRJ-4202,
PMTR-40076

SmartView

NEW: Added support for "SmartView for QRadar" extension.

PRJ-5784,
PRHF-611

Compliance

In some scenarios, the Compliance Blade checks the 'Parent rule for Domain's policy' placeholder as if it was a real rule and shows the rule index in the Firewall Best Practices relevant objects.

PRJ-5480,
PRJ-5482,
NAT-110

Security Gateway

NEW: Enhancement: NAT port exhaustion logs mechanism was updated. Refer to sk156852.

PRJ-4805,
PMTR-41392

Security Gateway

NEW: Added ability to enable NAT over specific IP address avoiding a source port allocation.

PRJ-6036,
PRJ-4165,
PMTR-39641

Security Gateway

In some scenarios, when the ICAP server on the Security gateway is enabled, some web pages do not load.

PRJ-4749,
PRHF-5313

Security Gateway

In a rare scenario, the FWK process unexpectedly exits during debug.

PRJ-946,
GAIA-4638

Security Gateway

Connectivity issues on some HTTPS sites (as login pages) when Security gateway is configured as proxy. Refer to sk147878.

PRJ-2919,
UP-293

Security Gateway

In a rare scenario, Security gateway may crash due to NULL pointer reference.

PRJ-5326,
PRJ-5433,
PMTR-42553

Security Gateway

Non-FQDN domain objects may not be enforced correctly when used in the Access policy along with updatable objects.

PRJ-5820,
PRJ-5821,
PMTR-37949

Security Gateway

In some scenarios, traffic is dropped with 'up_transaction_notify_clob failed' error in dmesg when Application Control is enabled.

PRJ-5312,
PRJ-5314,
NAT-137

Security Gateway

In a rare scenario, Security gateway freezes when IP pool NAT and VPN are used.

PRJ-4356,
PRJ-4405,
SWG-2208

Security Gateway

In a rare scenario, Security gateway crashes when proxy is enabled.

PRJ-1872,
PRJ-5114,
PRHF-3940

Security Gateway

In some scenarios, when using Hide NAT with GRE tunnel, packets going through this GRE tunnel may get dropped. Refer to sk154492.

PRJ-4398,
PRJ-4400,
PMTR-34813

Security Gateway

In some scenarios, traffic is dropped with "[ERROR]: network_classifier_handle_dag: failed to get uuid of DAG bogus_ip" error in dmesg.

PRJ-3426,
PMTR-35854

Security Gateway

In a rare scenario, changing the xmit-hash-policy of the bonding group while machine handling traffic, causes it to crash. Refer to sk154573.

PRJ-4180,
PRJ-4362,
SWG-2174

Security Gateway

Some Web sites cannot be opened when Content Awareness or Anti-Virus/Anti-Bot is enabled, and Security gateway is configured as proxy.

PRJ-4403,
PRJ-4650,
PMTR-40858

Security Gateway

In a rare scenario, when X-Forwarded-For (XFF) settings are enabled on one of the policy layers and on the Security Gateway object, traffic may be accepted although it should be dropped according to Access policy.

PRJ-771,
PRJ-6035,
SWG-1922

Security Gateway

In a rare scenario, memory usage may rise on Security gateway, when using service with resource with "Optimize URL logging" feature enabled. Refer to sk153052.

PRJ-4351,
PRJ-4352,
PMTR-41407

Security Gateway

Access rulebase may not be enforced properly when wildcard objects are used in source and destination columns. Refer to sk162692.

PRJ-5141,
PMTR-38249

Security Gateway

In some scenarios, traffic is dropped with "network_classifier_get_dynobjs_for_ip: failed to get UUIDs for IP 0.0.0.0" and "kfunc_ip_ranges_to_dynobj: network_classifier_get_dynobjs_for_ip failed" errors in dmesg when dynamic object is used in access policy.

  • Fix is relevant for Gaia 3.10 only.

PRJ-4114,
PRHF-2796

Security Gateway

In some scenarios, logs cannot be seen because the LOG_INDEXER process stopped working.

PRJ-3276,
PRJ-2310

Logging

Log Exporter filtering feature allows to decide which logs will be exported based on values from the various fields on the raw log.

PRJ-3210,
PRHF-4497

Logging

In some Full HA environment scenarios, the "Logserver <Cluster virtual IP> is disconnected" error pops up in SmartConsole log view.

PRJ-1325,
PRHF-3690

Logging

In some scenarios, when running mdsstart, the following error message is shown: "/opt/CPSmartLog-R80.20/bin/smartlogstop: line 65: /opt/CPmds-R80.20/customers//CPSmartLog-R80.20/log/smartlogRun.log: No such file or directory".

PRJ-1311,
PRHF-3681

Logging

In the Logs & Monitor view, the "File size" field is missing from the logs generated by Media Encryption & Port Protection Blade. Refer to sk157952.

PRJ-2019,
PRHF-2607

Logging

In some scenarios, when SAM activity is defined and a Log server receives a high amount of packets, the FWD process on the Log server unexpectedly exits.

PRJ-5338,
PRJ-5295

Logging

NEW: Added new Log Exporter feature to export links to the relevant log and log attachments (such as Forensics\TE report).

PRJ-4759,
PMTR-40677

IPS

In some scenarios, IPS update fails as a result of error in management server installation.

PRJ-6658,
PRJ-6659,
PRJ-6655

HTTPS Inspection

NEW: HTTP traffic performance enhancement on VSX environment when Gzip enforcement is used.

PRJ-5877,
PRJ-5609

HTTPS Inspection

In a rare scenario, Security Gateway may crash during non-compliant HTTP traffic.

PRJ-6078,
PRJ-6086

ClusterXL

After installing Jumbo HotFix Take 76 only on a standby member, it's outgoing traffic does not pass.

PRJ-4591,
PRJ-4592,
PMTR-41002

ClusterXL

In some scenarios, arp table is not synchronized with master MAC address after fail-over.

PRJ-5080,
PRJ-2152

ClusterXL

The message "fwlddist_debug_update_op: resetting to avoid overflow" should be printed only in debug mode since it's not an error.

PRJ-4584,
PRJ-5258,
PMTR-37812

ClusterXL

In some scenarios, installing policy in order to update the cluster topology during high load, causes the members to fail-over. Refer to sk154575.

PRJ-4409,
PRJ-4583,
PMTR-38208

ClusterXL

In some scenarios, when changing cluster topology and installing the policy, the cluster fails over. Refer to sk156335.

PRJ-5859,
PRJ-1848

SecureXL

In a rare scenario, Host destination entries are memory leaking when neighbor entry is in incomplete state. Refer to sk157252.

  • Fix is relevant for Gaia 3.10 only.

PRJ-5153,
PMTR-37736

SecureXL

In some scenarios, IGMP packets are not forwarded across bridge interfaces.

  • Fix is relevant for Gaia 3.10 only.

PRJ-5154,
PMTR-37727

SecureXL

In some scenarios, packets with IP options are not forwarded across bridge interfaces. Refer to Issue #3 in sk154892.

  • Fix is relevant for Gaia 3.10 only.

PRJ-2815,
PRHF-3608

SecureXL

On cluster, Drop templates are disabled on reboot. Refer to sk153412.

  • Fix is relevant for Gaia 3.10 only.

PRJ-5152,
02541089

SecureXL

In a rare scenario, Security gateway may freez / crash when a multicast routing is configured. Refer to sk119299.

  • Fix is relevant for Gaia 3.10 only.

PRJ-4783,
PRJ-4784,
PMTR-40553

SecureXL

NEW: "sim if" and "sim nonaccel" commands will be deprecated. Instead, "fwaccel if" and "fwaccel nonaccel" commands will be used to accommodate multiple SecureXL instances.

PRJ-6850,
PRJ-6851,
PMTR-25095

SecureXL

In some scenarios, the Security Gateway accepts the traffic, but no ARP request is sent. Refer to sk152093.

PRJ-6100,
PRJ-6101,
PRHF-5450

SecureXL

In some scenarios, SecureXL drops TCP packets with "Out of state" reason.

PRJ-5155,
PRJ-5156,
PMTR-23471

SecureXL

  • The "fwaccel conns" command has incorrect Help text.
  • The "fwaccel conns -n"command returns"invalid mask given" message.

PRJ-6779,
PRJ-6108,
PRHF-5706

SecureXL

In some scenarios, connection does not to expire correctly when NAT and some Software Blades are enabled.

PRJ-4360,
PRJ-4361,
PMTR-40826

SecureXL

In a rare scenario, Security gateway may crash if cpinfo reads from the /proc/ppk/cpls directory before SecureXL is initialized.

PRJ-6150,
PRJ-4564

SecureXL

NEW: Added new SecureXL Fast Accelerator for Non-Scalable Platforms. Refer to sk156672.

PRJ-834, PMTR-36031

CoreXL

In a rare scenario, Security gateway may freeze when "Drop Templates" or "DOS rate" feature is enabled.

PRJ-5469,
PRJ-5684,
PMTR-38358

SSL Inspection

In some scenarios, several applications are not matched correctly when HTTPS Inspection enabled and URL Filtering is in HOLD mode.

PRJ-5288,
PRJ-4758

URL Filtering

NEW: Improved scalability and resiliency of URL Filtering service.

PRJ-6857,
PRJ-6828,
SWG-2314

URL Filtering

In a rare scenario, RAD process fails to process new kernel requests.

PRJ-3614,
PRJ-4854,
ROUT-679

Routing

In some scenarios, OSPFv3 LS updates of the default route are not accepted by the Security gateway for Stub/TSA areas. Refer to sk161472.

PRJ-6063,
PRJ-6062,
PRHF-2798

Routing

In a rare scenario, the routed process may unexpectedly exit when a route with a local address as a nexthop is received.

PRJ-5551,
PRJ-5596,
PRHF-1739

Gaia OS

In some scenarios, Smart-1 405 and 410 appliances may show high voltage due to incorrect VBat thresholds.

PRJ-1030,
GAIA-5047

Gaia OS

Changing the xmit-hash-policy of the bond may cause all static arp entries to disappear from the arp -a output. Refer to sk152892.

PRJ-2191,
PRHF-5189

Gaia OS

Many "fwldbcast_new: too many hosts : 0" kernel messages appear in /var/log/messages file. Refer to sk153253.

PRJ-962,
PRJ-2789,
PRHF-2474

Gaia OS

In some scenarios, user cannot access terminal from WebUI in monitor role mode.

PRJ-6686,
PRJ-6687,
PRJ-6991,
PMTR-44076

Gaia OS

In some scenarios, Gaia restore on Multi-Domain Server fails with error "failed to edit update registry". Refer to sk163312.

PRJ-2819,
PMTR-39191

Gaia OS

While unplugging one of the Power supply cables on Smart-1 5150/5050/525 appliances a false 'No Read' message appears for ~5 seconds in both PSUs statuses (instead of Present/Input Lost/Absence).

PRJ-4156,
PRJ-5075,
PRHF-3929

Gaia OS

NEW: The ARP cache size limit in Clish was increased to 131072 hosts.

PRJ-4523,
PRJ-4524,
GAIA-5047

Gaia OS

Changing the xmit-hash-policy of the bond may cause all static arp entries to disappear from the arp -a output. Refer to sk152892.

PRJ-3122,
PMTR-38890

Endpoint Security

In some scenarios, Endpoint Security Clients are in "Disconnected" state after Endpoint Security Server upgrade. Refer to sk161113.

PRJ-2321,
EPS-21609

Endpoint Security

If there is a large amount of devices which are going to be removed from the Deleted Container, the server may fail to process the epmCommands, returning "FATAL: remaining connection slots are reserved for non-replication superuser connections" error.

PRJ-2014,
EPS-20841

Endpoint Security

In some scenarios, SmartEndpoint shows "Unknown Error" when trying to open the "User and Computers" Tab "Top Bots" and software deployment by policy reports. Refer to sk151932.

PRJ-5352,
PMTR-39950

Endpoint Security

In some scenarios, migrate_import fails with the "ERROR: Command completed with error code #2 and output: psql.bin: could not connect to server: No such file or directory" message in $UEPMDIR/logs/exportedFileManip*.log.

PRJ-2913,
EPS-21658

Endpoint Security

In some scenarios, when searching for a machine in SmartEndpoint and selecting it, a "Server Error" message appears. Refer to sk158432.

PRJ-1810,
PMTR-27831

VPN

NEW: Connectivity enhancements for Remote Access clients using internal Office mode allocation with a long timeout.

PRJ-4648,
PRJ-6593,
PRHF-4819

VPN

In some scenarios, traffic is not working over Site-to-Site VPN after an upgrade.

PRJ-2873,
PRJ-4726,
PMTR-38894

VPN

Connectivity improvement for Remote Access clients in environments with 3rd party VPN tunnels.

PRJ-3557,
VSX-1866

VSX

NEW: Added the option to configure reject routes via vsx_provisioning_tool on Scalable Platforms Appliances. Refer to sk151473.

PRJ-5922,
PRHF-6345

VSX

In some scenarios, IGMP traffic is dropped by "local interface address spoofing" in VSX HA. Refer to sk162953.

PRJ-4674,
PMTR-41221

VSX

VSX configuration cannot not be applied after upgrade from R77.x to R80.x, due to duplicated VSX routes.